Stabilize import safety, authentication, and fresh-install workflows - #3
Merged
Merged
Conversation
Prowlarr's /api/v1/search binds `categories` as an array of int, which
requires a repeated query parameter (categories=7000&categories=3030).
searchOnce used url.Values.Set with a comma-joined string, so any format
resolving to more than one category produced categories=7000%2C3030 and
Prowlarr rejected it with 400 Bad Request:
"categories": { "rawValue": "7000,3030",
"errors": [{ "errorMessage": "The value '7000,3030' is not valid." }],
"validationState": "invalid" }
librarry surfaces that upstream failure to the browser as a 502.
This hit audiobook searches (7000,3030) and the "any" format on every
query regardless of search term or indexer. Ebook searches were
unaffected only incidentally, because "7000" is a single value with no
comma to mis-encode.
Add categoryListForFormat, which splits the same list for use with
url.Values.Add. categoriesForFormat is retained for fetchIndexerFeed:
the Newznab feed endpoint takes a comma-joined `cat` parameter, which
is the correct convention there and must not change.
This was referenced Sep 16, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Completed-download handling could import an unrelated sibling or one chapter from a multipart book, then remove the source. This change requires an exact single-file payload and verified cleanup evidence, preserves import identity during rescans, and retains ambiguous data. It fixes the acquisition settings race, Prowlarr category requests, and mutations that could affect another client's download with the same external ID. The Prowlarr change preserves Zak Strassberg's authorship from PR #2.
Authentication fails closed when required persistence is unavailable. Credential/method updates and session revocation commit atomically; stale logins cannot recreate sessions after a password change. Environment-owned controls are locked in Settings, and malformed automation values fail startup instead of silently enabling a default. Status reports the real build, schema and authentication state.
Native completed imports now save an immutable manifest and use renewable leases. File/book/download records commit together; unfinished publications stay hidden from scanners. A process restart resumes the same destination after database failure. Explicit relational links preserve legacy evidence and report ambiguous associations without granting cleanup eligibility. Imports exposes saved plans, retries, failures and cleanup state.
Library queries retain imported books. Direct book/file lookup works beyond collection caps and distinguishes a missing book from an outage. Empty/error states, dialog focus and mobile navigation are improved. Hardcover GraphQL errors no longer masquerade as empty success. Runtime/frontend dependencies and installed container packages are updated.
Validation: full Go race suite with disposable Postgres, Go vet, six frontend tests/build, Compose rendering, and 15 desktop/mobile browser cases passed locally (one inapplicable desktop case skipped). A 10,001-book/file fixture verifies older direct links. Local ARM64 images at c62268f pass exact import, a forced final database-write failure with rollback, a real process restart/resume, hidden unfinished files, sibling/multipart rejection, source retention, rescans, repeat-import handling, isolated dump/restore including manifests/relationships, and forms/cookie/restart/Basic authentication. Additional tests cover expired leases, stale workers, changed bytes, missing sidecars and cleanup failures. Invalid auth and malformed automation settings exit before serving requests. Trivy reports zero OS findings; the API retains only a module-level advisory for unused x/crypto/openpgp, with no reachable/imported-package finding from govulncheck. npm audit reports zero findings.
CI now gates multi-platform publication on source checks, packaged fixture tests, and scans rejecting fixable high/critical image findings. The complete CI run passed on 7771862: verification, packaged qualification, and both AMD64/ARM64 image builds. PR builds were not published. Builds compile natively and target AMD64/ARM64 without emulating the compiler or frontend build.
This remains partial implementation of docs/stabilization-plan.md. Multipart grouping, crash-safe replacement, manual/Calibre recovery, temporary-stage reclamation, acquisition intents, resumable scans, broader metadata/compatibility/scale work, unified settings precedence, full workflow polish, live backup restore, deployment/rollback and the timed soak remain. Destination filesystems must support the atomic hard-link publication used by the candidate, including in copy mode; intended NAS mounts still require qualification. See docs/reviews/2026-09-15-implementation.md for evidence and remaining gates. No production deployment, public release or soak is claimed.